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Top Stories 

• Service on the Number 1, 2, and 3 trains in New York City was suspended for several 
hours April 8-9 in the West Village area of the city due to flooding inside the 14th Street 
Station caused by a water main break. - WCBS 2 New York City (See item 9) 

• Sabra Dipping Co., LLC voluntarily issued a recall April 8 for about 30,000 cases of its 
Classic Hummus due to possible Listeria monocytogenes contamination. - U.S. Food and 
Drug Administration (See item 15) 

• Officials reported that more than 100 million gallons of sewage and storm water spilled 
into the Ohio River April 9 after a water treatment plant in Kentucky was knocked out of 
service following a fire. - Louisville Courier-Journal (See item 17) 

• Researchers discovered that an email campaign targeting users worldwide utilizes a 
combination of the Upatre downloader and Dyre banking trojans to gain information about 
compromised systems and intercept online banking credentials. - Help Net Security (See 
item 27) 
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Energy Sector 



1. April 8, KVU 7 Amarillo - (Texas) Xcel: Power plant fire shouldn’t affect residents. 
An April 8 fire at Xcel Energy’s Harrington Generating Station in Amarillo began in 
the Unit 1 cooling tower and spread into three cells before it was contained. Unit 1 is 
operating at about half capacity while authorities investigate the cause of the fire. 
Source: http ://w w w .connectamarillo .com/news/story. aspx?id= 1188553 

2. April 8, Forum of Fargo-Moorhead - (North Dakota) PSC approves two pipelines. 
The North Dakota Public Service Commission approved a 12-inch Hiland Crude LLC- 
owned crude oil line in McKenzie County that will transport oil from smaller gathering 
systems and truck facilities to other rail and pipeline destinations April 8. The 
commission also approved a 6-inch Caliber Midstream Partners-owned pipeline to 
transport gas liquids from the Hay Butte Gas Plant to ONEOK Partners’ Bakken NGL 
Pipeline. 

Source: http://www.inforum.com/news/37 1 8 124-psc-approves-two-pipelines 
For another story, see item 23 
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Chemical Industry Sector 

Nothing to report 
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Nuclear Reactors, Materials, and Waste Sector 

3. April 8, Charlotte Business Journal - (North Carolina) Duke Energy reports small 
hairline fault in reactor head at Harris nuclear plant to the NRC. A spokesman for 
Duke Energy reported to the U.S. Nuclear Regulatory Commission April 7 that the 
company discovered a hairline fault in the reactor head of the Shearon Harris nuclear 
plant in New Hill while it was offline for refueling and regular inspection. The fault 
will be repaired while the plant remains offline. 

Source: http://www.biziournals.com/charlotte/blog/energv/2015/04/duke-energv- 
reports-small-hairline-fault-in.html 

4. April 7, Bloomberg News - (Maryland) Washington Power falls as grid adjusts to 
transformer failure. The U.S. Nuclear Regulatory Commission reported April 7 that a 
transformer failure caused power flows on transmission lines to the Calvert Cliffs plant 
in Maryland to drop, triggering automated emergency systems to shut down both 
reactors at the site. Calvert Cliffs’ officials stated that both reactors were ready to 
resume output following the brief disruption. 

Source: http://www.bloomberg.com/news/articles/2015-04-07/boston-spot-power- 
gains-as-fuel-costs-rise-in-cooler- weather 
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Critical Manufacturing Sector 

Nothing to report 



[ Return to top ] 



Defense Industrial Base Sector 

5. April 8, U.S. Securities and Exchange Commission - (International) SEC charges 
Oregon-based defense contractor with FCPA violations. Oregon-based FLIR 
Systems Inc., agreed April 8 to pay more than $9.5 million in penalties to settle U.S. 
Securities and Exchange Commission (SEC) charges that the infrared technology 
developer violated the Foreign Corrupt Practices Act. The SEC alleged that the 
company earned more than $7 million in profits from sales influenced by improper 
travel and gifts to foreign officials between 2008 and 2010. 

Source: http ://www . sec . gov/news/pressrelease/20 1 5-62 .html 

[ Return to top ] 

Financial Services Sector 

6. April 9, Easton Express-Times - (Pennsylvania; New York) 1-78 traffic stop nets 
wanted man with 75 fake credit cards in pants, police say. A New York man was 
arrested and charged April 7 after Pennsylvania State Police officers found 75 fake 
credit cards in his possession during a traffic stop on Interstate 78 in Lehigh County. 
The man was sent to the county jail and will be extradited to New York due to a 
separate warrant. 

Source: http://www.lehighvalleylive.com/lehigh-county/index.ssf/2015/04/i- 
78 traffic stop nets fugitiv.html 

7. April 8, South Florida Business Journal - (Florida) 4 Miami residents indicted in 
international mortgage fraud scheme. The U.S. Attorney’s Office for the Southern 
District of Florida announced the indictment of 6 individuals and 3 companies April 8 
in reference to an international mortgage fraud scheme in which the individuals 
allegedly used fraudulent loan applications and other documents to apply for over $9 
million in mortgage loans from Chevy Chase Bank, JP Morgan Chase Bank, and 
Washington Mutual Bank for residential properties in Miami-Dade and Palm Beach 
counties from October 2004-May 2007. 

Source: http://www.biziournals.com/southflorida/news/2015/04/08/4-miami-residents- 
indicted-in-intemational.html 



For another story, see item 27 
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Transportation Systems Sector 



8. April 9, WMAQ 5 Chicago - (Illinois) Severe storms take aim at Chicago. Fog and 
rain April 9 prompted the cancelation of 370 flights at Chicago O’ Hare International 
Airport and at least 1 flight at Midway International Airport, while several flights were 
delayed at both airports. 

Source: http://www.nbcchicago.com/weather/stories/Severe-Storms-Possible-in- 
Chicago-Area-Thursday-299068501.html 

9. April 9, WCBS 2 New York City - (New York) 500 evacuated from subway after 
West Village water main break; some service halted. Service on the New York City 
subway system’s Number 1, 2, and 3 trains was suspended for several hours April 8-9 
throughout a stretch of the city’s West Village area due to flooding inside the 14th 
Street Station caused by a water main break. About 500 passengers were safely 
evacuated from trains entering the station before the suspension, and crews drained 
water from the station’s tracks before resuming operations. 

Source: http://newvork.cbslocal.com/2015/04/Q8/west-village-water-main-break- 
reroutes-no-1 -train/ 

10. April 8, Sacramento Bee - (California) CHP, FBI investigate two Sacramento 
freeway pipe bombs. California Highway Patrol officials reported April 8 that a pipe 
bomb found at the Arden Way off-ramp along the Capital City Freeway prompted the 
road to close for 3 hours April 6 while authorities rendered the device safe. The 
incident is being investigated as possibly being connected with a March 4 incident 
where a pipe bomb that was found on a Highway 50 off-ramp in Sacramento was 
disabled without incident. 

Source: http://www.sacbee.com/news/local/crime/articlel7889365.html 

11. April 8, WAFB 9 Baton Rouge - (Louisiana) 1-10 westbound reopens at LA-415 after 
crash shuts down interstate on Basin Bridge. The Basin Bridge on Interstate 10 
westbound near Whiskey Bay, Louisiana, was closed for several hours April 8 while 
officials inspected the structural integrity of the bridge following an accident that 
involved at least two semi-trucks and one pick-up truck. Two individuals were 
transported to area hospitals for injuries. 

Source: http://www.wafb.com/story/28752742/i-10-westbound-reopens-at-la-415-after- 
crash-shuts-down-interstate-on-basin-bridge 
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Food and Agriculture Sector 

12. April 9, U.S. Department of Agriculture - (Oregon; Washington) Vern’s and Sons 
Food Service recalls beef and chicken products produced without benefit of 
inspection. Vem’s and Sons Food Service recalled April 8 about 450 pounds of its 
Great Pacific -branded Beef Verde Burrito and Chicken Chipotle Burrito products that 
were produced without the benefit of inspection by the U.S. Department of Agriculture. 
The recalled products were distributed to retailers in Oregon and Washington. 
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Source: http://www.fsis.usda.gov/wps/portal/fsis/topics/recalls-and-public-health- 
alerts/recall-case-archive/archive/2015/recall-Q56-201 5-release 



13. April 9, U.S. Department of Agriculture - (Illinois; Indiana; Wisconsin) La 
Guadalupana Wholesale Co., Inc. recalls pork and chicken products due to 
misbranding and an undeclared allergen. The Food Safety and Inspection Service 
announced April 8 that La Guadalupana Wholesale Co., Inc., recalled about 34,923 
pounds of its pork and chicken tamale products due to undeclared egg whites and 
misbranding. The recalled products were shipped to retail locations in Illinois, Indiana, 
and Wisconsin. 

Source: http://www.fsis.usda.gov/wps/portal/fsis/topics/recalls-and-public-health- 
alerts/recall-case-archive/archive/2015/recall-057-201 5-release 



14. April 8, Associated Press - (Minnesota) Jennie-O turkey farm in Minnesota hit by 
deadly bird flu. The U.S. Department of Agriculture (USDA) confirmed April 8 the 
presence of the highly pathogenic H5N2 stain of avian influenza in one barn at a large 
Jennie-O-Turkey Store operation in Meeker County. Officials are working to determine 
what to do with the turkeys housed in the other 1 1 bams at the facility. 

Source: http://www.utsandiego.com/news/2015/apr/08/iennie-o-turkey-farm-in- 
minnesota-hit-by-deadly/ 



15. April 8, U.S. Food and Drug Administration - (National) Sabra Dipping Company 
issues nationwide voluntary recall of select SKUs of its Classic Hummus. The U.S. 
Food and Drug Administration reported April 8 that Sabra Dipping Co., LLC 
voluntarily issued a recall for about 30,000 cases of its Classic Hummus due to possible 
Listeria monocytogenes contamination. The recalled products were distributed to retail 
outlets, including food service accounts and supermarkets nationwide. 

Source: http://www.fda. gov/S afety/Recalls/ucm44 1863 .htm 

16. April 8, U.S. Food and Drug Administration - (Texas) World Wide Gourmet Foods 
issues allergy alert on undeclared wheat and soy in Central Market Teriyaki 
Salmon Jerky. The U.S. Food and Drug Administration announced April 8 that 
Washington-based World Wide Gourmet Foods issued a recall for 2,916 packages of its 
Central Market Teriyaki Salmon Jerky due to undeclared wheat and soy caused by 
mislabeling. The affected product was sent to H.E.B. retail locations in Texas from 
February 27- April 3. 

Source: http://www.fda.gov/Safety/Recalls/ucm441838.htm 
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Water and Wastewater Systems Sector 

17. April 9, Louisville Courier-Journal - (Kentucky) Huge sewage flow hits Ohio River 
after blast. The Metropolitan Sewer District (MSD) reported that more than 100 
million gallons of sewage mixed with storm water was spilled, and continues spilling 
into the Ohio River April 9 after the Morris Forman Water Quality Treatment Center in 
Kentucky suffered electrical and mechanical damage that knocked it out of service 
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following an April 8 explosion and fire. Authorities warned the public to avoid contact 
with the river near the discharge area, and stated that the treatment process will resume 
once repairs are completed. 

Source: http://www.courier- 

ioumal.com/storv/tech/science/environment/2015/04/09/msd-spilling-huge-sewage- 
flow-ohio-river/255 13365/ 



18. April 9, WSVN 7 Miami - (Florida) Water advisory issued for Haulover Park beach 
goers. The Florida Department of Health issued an advisory at the Haulover Park North 
and South Beaches, near Miami Beach, due to high bacteria levels found in water 
samples April 8. 

Source: http://www.wsvn.com/storv/28753678/water-advisorv-issued-for-haulover- 
park-beach- goers 

19. April 8, Concord Independent Tribune - (North Carolina) 1,500 gallons of wastewater 
spills in Mount Pleasant. Officials reported that about 1,500 gallons of untreated 
wastewater spilled from a cracked, underground force main serving the Barringer Drive 
lift station into a tributary of Adams Creek in Mount Pleasant April 7. Public works 
officials stated that there is no danger to humans, livestock, or aquatic animals, and that 
they are monitoring the situation. 

Source: http://www.independenttribune.com/news/gallons-of-wastewater-spills-in- 
mount-pleasant/article cd57dbb8-de04-l Ie4-87d6-fb46a367c5bc.html 

20. April 8, Baltimore Brew - (Maryland) Sewage spill reported tonight in East 
Baltimore. The Baltimore Department of Public Works worked to stem an ongoing 
sewer overflow of 100 gallons per minute into Armistead Run, a tributary of Herring 
Run which flows into Back River, and posted warning signs of the contamination by 
the stream April 8. The Maryland Department of the Environment was alerted of the 
overflow which officials expect will discharge more than 10,000 gallons of sewage 
before repairs are complete. 

Source: https://www.baltimorebrew.com/2015/04/08/sewage-spill-reported-tonight-in- 
east-baltimore/ 
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Healthcare and Public Health Sector 

Nothing to report 
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Government Facilities Sector 

21 .April 8, KOTV 6 Tulsa - (Oklahoma) Five hurt when Tulsa school bus rolls over on 
Highway 75. Four Roosevelt Elementary School students and the bus driver were 
transported to an area hospital with injuries after the school bus began to slip sideways 
on Highway 75 in Tulsa and toppled down a hill April 8. Police stated that rain and 
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speed were both factors in the accident. 

Source: http://www.newson6.com/story/28753788/tps-bus-rolls-over-kids-on-board 



22. April 8, KDKA 2 Pittsburgh - (Pennsylvania) Seton-LaSalle HS closed due to violent 
threat. Seton-LaSalle High School in Mt. Lebanon remained closed April 9 after 
several faculty members and the principal received an email threatening violence 
against students and staff, prompting officials to cancel classes April 8. The FBI will 
determine when the school will reopen, school personnel stated. 

Source: http://pittsburgh.cbslocal.com/2015/04/08/seton-lasalle-hs-closed-due-to- 
violent-threat/ 



For another story, see item 23 
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Emergency Services Sector 

23. April 8, Associated Press - (South Carolina) Coast Guard doing oil spill training on 
SC coast. The U.S. Coast Guard, the National Oceanic and Atmospheric 
Administration, South Carolina emergency responders, and other Federal partners are 
participating in oil spill training at Melton Peter Demetre Park in Charleston beginning 
April 8 through April 10 to practice techniques for how to handle coastal oil spills and 
the aftermath, and how to conduct post-event assessments of the shoreline. 

Source: http://www.carolinalive.com/news/story.aspx?id=l 188563 

24. April 8, Modesto Bee - (California) Equipment stolen from fire station west of 
Modesto. Authorities are asking for the public’s help in identifying the individuals 
responsible for stealing an estimated $30,000 in equipment from the Woodland Avenue 
Fire Protection District station in Modesto, which included portable radios and 
firefighting gear, by prying open a locked door and gaining entry into the station April 
7. 

Source: http://www.modbee.com/news/local/crime/articlel7911802.html 
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Information Technology Sector 

25. April 9, Softpedia - (International) Over 100 forum websites foist poorly detected 
malware. Security researchers at Cyphort discovered a supposed click-fraud campaign 
that exploits Web forums running outdated versions of vBulletin or IP Board software 
to use malicious code to direct visitors to a landing page hosting the Fiesta exploit kit 
(EK) to deliver Gamarue and FleerCivet malware that steals information and injects 
backdoor trojans. The malware ensures persistence by avoiding virtual environments 
and disabling security settings on compromised systems, and exploits vulnerabilities 
found in Internet Explorer and in Adobe Flash Player version 16.0.0.296 and earlier. 
Source: http://news.softpedia.com/news/Over-100-Forum-Websites-Foist-Poorly- 
Detected-Malware-47 8020. shtml 
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26. April 9, Threatpost - (International) Apple iOS 8.3 includes long list of security fixes. 
Apple released iOS 8.3 for iPhone and iPad users patching over three dozen 
vulnerabilities, including flaws in the mobile operating system’s kernel, several bugs in 
WebKit, and a number of code-execution bugs. 

Source: https://threatpost.com/apple-ios-8-3-includes-long-list-of-securitv-fixes/112072 

27. April 9, Help Net Security - (International) Deadly combination of Upatre and Dyre 
trojans still actively targeting users. ESET researchers discovered that an email 
campaign targeting users worldwide utilizes a combination of the Upatre (Waski) 
downloader and Dyre/Dyreza banking trojans delivered via simple spam emails to gain 
information about compromised systems and intercept online banking credentials. 
Researchers believe that the scheme is part of the larger, previously discovered Dyre 
Wolf campaign that has targeted businesses around the world. 

Source: http://www.net-security.org/malware news.php?id=301 1 

28. April 8, Securityweek - (International) Google Chrome extension criticized for data 
collection. Security researchers at ScrapeSentry and Heimdal Security reported that the 
Webpage Screenshot Google Chrome third-party extension contained malicious code 
that allowed for copies of all browser data to be sent to a server in the U.S. Google 
removed the extension from the Chrome Web Store, and Webpage Screenshot claimed 
that the information was only used for marketing and development purposes. 

Source: http://www.securitvweek.com/google-chrome-extension-criticized-data- 
collection 



29. April 8, Threatpost - (International) Two NTP key authentication vulnerabilities 
patched. Network Time Protocol (NTP) patched two vulnerabilities that allowed 
attackers to leverage symmetric key authentication flaws to bypass message 
authentication code (MAC) to send packets to clients. The second vulnerability utilized 
symmetric key authentication to create denial-of-service (DoS) conditions when 
peering hosts receive packets with mismatched timestamps. 

Source: https://threatpost.com/two-ntp-key-authentication-vulnerabilities- 
patched/ 112067 



Internet Alert Dashboard 



To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or 
visit their Web site: http://www.us-cert.gov 

Information on IT information sharing and analysis can be found at the IT IS AC (Information Sharing and 
Analysis Center) Web site: http://www.it-isac.org 
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Communications Sector 

30. April 8, SCMagazine - (International) FCC fines AT&T $25M for call center 

breaches. AT&T agreed to pay $25 million in penalties April 8 as part of an agreement 
with the U.S. Federal Communications Commission to settle allegations that the 
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company’s call centers in Columbia, the Philippines, and Mexico disclosed the names 
and full or partial Social Security numbers of 280,000 customers from 2013-2014. The 
personal information was used by call center workers to obtain codes that unlock 
handsets of AT&T phones that were shared with co-conspirators in a stolen cell phone- 
trafficking scheme. 

Source: http://www.scmagazine.com/att-fined-by-fcc-for-breaches-in-three-call- 
centers/article/408 114/ 
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Commercial Facilities Sector 

31 .April 8, Austin Business Journal - (National) 2 Austin hotels hit by data breach; 
credit card info at risk. White Lodging Services Corp., announced April 8 that 
attackers installed malware on the point-of-sale (PoS) systems at food and beverage 
outlets in 10 of the company’s hotels, and warned customers that their names and 
financial information may have been unlawfully accessed from July 3, 2014 to 
February 6, 2015. The breach remains under investigation by the company and law 
enforcement. 

Source: http://www.bizioumals.com/austin/blog/techflash/2015/04/2-austin-hotels-hit- 
by-data-breach-credit-card.html?page=all 
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Dams Sector 



32. April 9, Fredericksburg Free Lance-Star - (Virginia) Culpeper gets federal funds to 
upgrade dams. The U.S. Department of Agriculture announced April 8 that the town 
of Culpeper will receive as much as $10.5 million in Federal funds to upgrade the dams 
on Mountain Run Lake and Lake Pelham. Both of the dams were reclassified as “high 
hazard” structures in 2014 due to increased development downstream of the reservoirs 
which increases the risk of loss in case of an unforeseen incident. 

Source: http://www.fredericksburg.com/news/local/culpeper/culpeper-gets-federal- 
funds-to-upgrade-dams/article fl0c8928-20d4-5b32-bc61-70de0ae6f362.html 
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NTAS 



NO ACTIVE ALERTS 
www.DHS.gov/alerts 
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About the reports - The DHS Daily Open Source Infrastructure Report is a daily [Monday through Friday] 
summary of open-source published information concerning significant critical infrastructure issues. The DHS Daily 
Open Source Infrastructure Report is archived for 10 days on the Department of Homeland Security Web site: 
http://www.dhs.gov/IPDailvReport 

Contact Information 

Content and Suggestions: Send mail to cikr.productfeedback@hQ.dhs.gov or contact the DHS 

Daily Report Team at (703) 942-8590 

Subscribe to the Distribution List: Visit the DHS Daily Open Source Infrastructure Report and follow 

instructions to Get e-mail updates when this information changes . 

Removal from Distribution List: Send mail to support@ govdeliverv.com . 



Contact DHS 

To report physical infrastructure incidents or to request information, please contact the National Infrastructure 
Coordinating Center at nicc@hq.dhs.gov or (202) 282-9201. 

To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or visit 
their Web page at www.us-cert.gov . 

Department of Homeland Security Disclaimer 

The DHS Daily Open Source Infrastructure Report is a non-commercial publication intended to educate and inform 
personnel engaged in infrastructure protection. Further reproduction or redistribution is subject to original copyright 
restrictions. DHS provides no warranty of ownership of the copyright, or accuracy with respect to the original source 
material. 
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